Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3wq7-jqg2-g9mh

больше 3 лет назад

Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wq7-2q97-v54v

почти 4 года назад

SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

EPSS: Низкий
github логотип

GHSA-3wq6-8f7g-92vm

больше 3 лет назад

HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.

EPSS: Низкий
github логотип

GHSA-3wq5-3f56-v5xc

почти 3 года назад

Mattermost vulnerable to information disclosure

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wq5-2gjw-q95m

больше 3 лет назад

Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Floating Div plugin <= 3.0 at WordPress.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3wq4-hqw7-6x4f

3 месяца назад

An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensitive information via the login error messages

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wq4-8fhv-h6wv

6 месяцев назад

Missing Authorization vulnerability in Drupal Layout Builder Advanced Permissions allows Forceful Browsing.This issue affects Layout Builder Advanced Permissions: from 0.0.0 before 2.2.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3wq4-5xg6-q6v6

5 месяцев назад

SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a POST request using the parameters “mpsCentroin”, “mpsEmpresa”, “mpsProyecto”, and “mpsContrata” in “/servicios/autorizaciones.asmx/mfsRecuperarListado”.

EPSS: Низкий
github логотип

GHSA-3wq3-fv46-cvpq

почти 4 года назад

Race condition in run_posix_cpu_timers in Linux kernel before 2.6.16.21 allows local users to cause a denial of service (BUG_ON crash) by causing one CPU to attach a timer to a process that is exiting.

EPSS: Низкий
github логотип

GHSA-3wq3-9c8f-wfpw

больше 1 года назад

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-3wq3-8mrj-pgjf

больше 3 лет назад

Directory traversal vulnerability in the Management Console on the Symantec NetBackup (NBU) appliance 2.0.x allows remote attackers to read arbitrary files via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3wq2-hvxm-x2c4

больше 3 лет назад

Unspecified vulnerability in Oracle Sun Solaris 3.3 and 4.2 allows local users to affect availability via unknown vectors related to DevFS.

EPSS: Низкий
github логотип

GHSA-3wq2-f93g-wx78

больше 3 лет назад

Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3wpx-9425-3jrg

больше 3 лет назад

The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.

EPSS: Средний
github логотип

GHSA-3wpw-8xfm-9j79

около 4 лет назад

Open Design Alliance Drawings SDK before 2022.12.1 mishandles the loading of JPG files. Unchecked input data from a crafted JPG file leads to memory corruption. An attacker can leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3wpv-xcvc-6543

почти 4 года назад

An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted DHCP packet can lead to authentication bypass. An attacker can DHCP poison to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wpv-gh9g-2c8q

почти 4 года назад

Multiple PHP remote file inclusion vulnerabilities in Webradev Download Protect 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[RootPath] parameter to (1) Framework/EmailTemplates.class.php, (2) Customers/PDPEmailReplaceConstants.class.php, and (3) Admin/ResellersManager.class.php in includes/DProtect/.

EPSS: Низкий
github логотип

GHSA-3wpr-g54v-cr6j

11 месяцев назад

A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been declared as critical. This vulnerability affects the function save_users of the file /classes/Users.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3wpq-r344-mg23

почти 4 года назад

Cross-site scripting (XSS) vulnerability in index.php in the eWebsite eWeather (Weather) module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the chart parameter to modules.php.

EPSS: Низкий
github логотип

GHSA-3wpq-gjx8-r7c8

больше 1 года назад

Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can delete rules of other users affecting the integrity of the application. Confidentiality and Availability are not affected.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wq7-jqg2-g9mh

Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3wq7-2q97-v54v

SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3wq6-8f7g-92vm

HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3wq5-3f56-v5xc

Mattermost vulnerable to information disclosure

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-3wq5-2gjw-q95m

Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Floating Div plugin <= 3.0 at WordPress.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wq4-hqw7-6x4f

An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensitive information via the login error messages

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3wq4-8fhv-h6wv

Missing Authorization vulnerability in Drupal Layout Builder Advanced Permissions allows Forceful Browsing.This issue affects Layout Builder Advanced Permissions: from 0.0.0 before 2.2.0.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3wq4-5xg6-q6v6

SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a POST request using the parameters “mpsCentroin”, “mpsEmpresa”, “mpsProyecto”, and “mpsContrata” in “/servicios/autorizaciones.asmx/mfsRecuperarListado”.

0%
Низкий
5 месяцев назад
github логотип
GHSA-3wq3-fv46-cvpq

Race condition in run_posix_cpu_timers in Linux kernel before 2.6.16.21 allows local users to cause a denial of service (BUG_ON crash) by causing one CPU to attach a timer to a process that is exiting.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3wq3-9c8f-wfpw

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1

CVSS3: 5.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-3wq3-8mrj-pgjf

Directory traversal vulnerability in the Management Console on the Symantec NetBackup (NBU) appliance 2.0.x allows remote attackers to read arbitrary files via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wq2-hvxm-x2c4

Unspecified vulnerability in Oracle Sun Solaris 3.3 and 4.2 allows local users to affect availability via unknown vectors related to DevFS.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wq2-f93g-wx78

Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.

CVSS3: 5.4
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3wpx-9425-3jrg

The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.

14%
Средний
больше 3 лет назад
github логотип
GHSA-3wpw-8xfm-9j79

Open Design Alliance Drawings SDK before 2022.12.1 mishandles the loading of JPG files. Unchecked input data from a crafted JPG file leads to memory corruption. An attacker can leverage this vulnerability to execute code in the context of the current process.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3wpv-xcvc-6543

An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted DHCP packet can lead to authentication bypass. An attacker can DHCP poison to trigger this vulnerability.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3wpv-gh9g-2c8q

Multiple PHP remote file inclusion vulnerabilities in Webradev Download Protect 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[RootPath] parameter to (1) Framework/EmailTemplates.class.php, (2) Customers/PDPEmailReplaceConstants.class.php, and (3) Admin/ResellersManager.class.php in includes/DProtect/.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3wpr-g54v-cr6j

A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been declared as critical. This vulnerability affects the function save_users of the file /classes/Users.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 7.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-3wpq-r344-mg23

Cross-site scripting (XSS) vulnerability in index.php in the eWebsite eWeather (Weather) module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the chart parameter to modules.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3wpq-gjx8-r7c8

Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can delete rules of other users affecting the integrity of the application. Confidentiality and Availability are not affected.

CVSS3: 4.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу